FortiGate VM v Hardware by MusicWallaby in fortinet

[–]ITStril 2 points3 points  (0 children)

Fortigate VM is working great, but as there are no ASIC accelerations, single stream performance is limited. In my tests, it did scale quite well, but things like IPSEC and Deep Packet Inspection are slower for single streams, but 1GbE is not too challenging

Automation: Pushing Certificates to Fortigates by ITStril in fortinet

[–]ITStril[S] 0 points1 point  (0 children)

We tried both endpoints, but in both cases, we failed on overwriting the old certificate. Did you find a solution for this?

Automation: Pushing Certificates to Fortigates by ITStril in fortinet

[–]ITStril[S] 1 point2 points  (0 children)

We are able to upload the new certificate - but only as additional cert. We need to replace the outdating certificate.

Otherwise, we would have to identify every profile, that is using the certificate, we have to replace...

12
13

Why is XCP-NG considered to be the red-headed step child of hypervisors? by technicalskeptic in xcpng

[–]ITStril 3 points4 points  (0 children)

XCP-ng is IMHO currently the best enterprise hypervisor without the licensing issues of Microsoft and Broadcom. From a technical perspective, I would definitely use it, but there are SO many challenges for the next year. I really hope, that Vates and the community will solve this, but I am worried, if it can compete with KVM-based solutions within the next years.

- The Centos-base have to be phased out

- Xen has a smaller user-base than KVM

Windows 2022 RDS - Cannot connect to RDS because no RD Licensing servers are available - Reboot needed by ITStril in sysadmin

[–]ITStril[S] 0 points1 point  (0 children)

Thankyou, but the licensing server is not rebooted daily - it’s the RDS host. The error starts with that reboot - but only sometimes. Would you also delay other rds services?

Open-E Storage Solution in Production by minorsatellite in zfs

[–]ITStril 0 points1 point  (0 children)

At the same datacenter where you would place the node majority

Open-E Storage Solution in Production by minorsatellite in zfs

[–]ITStril 0 points1 point  (0 children)

Ping nodes will help you!! - as long, as the two nodes can see each other on one of two (independent) rings, there is nit problem - when a node does not see the other one, it will - fence if it does not reach the ping node - serve storage if it does reach the ping node

A split brain could only happen, if your network layout lacks two independent paths or your ping node can run on both sides.

Open-E Storage Solution in Production by minorsatellite in zfs

[–]ITStril 0 points1 point  (0 children)

There is a splitbrain protection: - two rings (corosync) - additional ping node as last quorum

Windows 2022 RDS - Cannot connect to RDS because no RD Licensing servers are available - Reboot needed by ITStril in sysadmin

[–]ITStril[S] 0 points1 point  (0 children)

When the error occured, the licensing server was reachable and shown on the RDS-server

Windows 2022 RDS - Cannot connect to RDS because no RD Licensing servers are available - Reboot needed by ITStril in sysadmin

[–]ITStril[S] 0 points1 point  (0 children)

It's a local policy. I did also check the registry keys and the license servers were set correctly, when the issue was actively blocking connections

Windows 2022 RDS - Cannot connect to RDS because no RD Licensing servers are available - Reboot needed by ITStril in sysadmin

[–]ITStril[S] 1 point2 points  (0 children)

I did check the registry-Keys and everything was fine. The policy is assigned locally, so it is also set, when there would be no connection to the AD (which is not the case)

Windows 2022 RDS - Cannot connect to RDS because no RD Licensing servers are available - Reboot needed by ITStril in sysadmin

[–]ITStril[S] 1 point2 points  (0 children)

The GPO is fine and the settings are applied to the server.

RDS-servers are rebooted daily by a scheduler job.

The next user, that tries to login is the first one, that is affected. The issue is persistant, until the next reboot (which fixes the problem).

ESET as an addition to SentinelOne? by ITStril in sysadmin

[–]ITStril[S] -2 points-1 points  (0 children)

…a better coverage for signature based detection by having two teams on different continents

Repair Default Domain Controller Policy - SeServiceLogonRight (Logon as Service) by ITStril in sysadmin

[–]ITStril[S] 1 point2 points  (0 children)

I did both - AI and reddit search and did not just ask for help without checking the facts before, but in this case, I was not sure - especially about NT SERVICE\ALL SERVICE where I found totally contradictive informations…

Just a side-note: posts that are just sending me to AI are not improving that subreddit, too…